CVE-2017-8205

HIGH

Honor 9 Firmware < Stanford-AL10C00B175 - Integer Overflow in Bastet Driver

Title source: llm
STIX 2.1

Description

The Bastet driver of Honor 9 Huawei smart phones with software of versions earlier than Stanford-AL10C00B175 has integer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP which has the root privilege; the APP can send a specific parameter to the driver of the smart phone, causing arbitrary code execution.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101963

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 24.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (2)
huawei/honor_9_firmware < stanford-al10c00b175
Huawei Technologies Co., Ltd./Honor 9 Versions earlier than Stanford-AL10C00B175
Published Nov 22, 2017
Tracked Since Feb 18, 2026